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Recently, there have been a considerable interest in 
a quantum key distribution (QKD) developed by us, 
which we call the KKKP protocol due to initials of the 
authorsllj. The KKKP protocol is based on random po- 
larizations and three-way communications between Alice 
and Bob, two legitimate users of the key. In 1] we ex- 
tended the KKKP protocol in order to make it robust 
against the impersonation attack by employing a set of 
two pulses to embody a qubit. Bob puts his private infor- 
mation s by random shuffling and Alice puts her private 
information b by random blocking. Then Bob's final mea- 
surement outcome I depends on Alice's key k and those 
private information s and b: I = s (B b (B k. Imper- 
sonating Eve can get b (B k but she does not know the 
shuffling parameter s so that there should be an error 
in Bob's measurement outcome. However, Zhang et al. 
recognized that because the shuffling factors of the first 
and second pulses are strongly correlated (the former be- 
ing s and the latter being s© 1), impersonating Eve does 
not need to know s to send correct information to Bob 
after reading b (B k. Then, when the blocking factor b is 
announced through the public channel. Eve gets the keys 
without causing any error to Bob's reading of the key. 

Here, we slightly modify the KKKP protocol for Bob 
to give two independent shuffling factors to the first and 
second pulses respectively. In this way, we do not lose all 
the advantages and basic philosophy of the KKKP proto- 
col while we build its security against the impersonation 
attack: 

(Q.l) Alice prepares two qubits in = \0i) (g) |02)- 
(Q.2) Upon reception of the two qubits. Bob applies ran- 
dom shuffling Uy{(j) + (-l)^i7r/4) ® Uyicj) + (-l)^27r/4), 
where Si = {0, 1} , (i = 1,2), are two independent ran- 
dom numbers. He sends the qubits back to Alice. 
(Q.3) Upon reception of the pulses, Ahce apphes 
Uyi-Oi + (-l)'^V/4) ® Uyi-02 + (-l)'^'® V/4) where k e 
{0, 1} is the key bit. Alice blocks one of the qubits, after 
which the surviving qubit is given by 

|</)+(-l)^''V4+(-l)^®'®'V4), (1) 

where b is the blocking factor to let the first (6=1) or 
the second pulse (& = 2) go. 

(Q.4) Bob receives the qubit and applies Uy{~(f)) on 
them before he measures it. The measurement outcome 
is given by Z — Sb(Bk(Bb. The key is given hy k = Sb(Bl(Bb. 



%item [(Q.5)] (Q.5) After repeating N times from (Q.l) 
to (Q.4), Alice announces blocking factors b through a 
public channel and Bob verifies the shared key by ex- 
changing the hash value of the key. 

Now, we show that the attack proposed by Zhang et 
al. is easily noticed in the QKD modified as above. 
(Q.l') After (Q.l), Eve intercepts and stores the both 
pulses from Alice in "set El". Thus Eve has El={|6'i) 
^2)}- Eve sends to Bob two pulses originally prepared 
by her with random angles 9'i, 02- 

(Q.2') After step (Q.2), Eve intercepts both pulses from 
Bob and stores them in "set E2" after compensating 
with the angles —9[, — 62- Eve then has E2={|0 -|- 
{-iy^7T/4) (g) 10 + {-iy^n/4:)}. Eve needs to guess two 
random parameters si and S2- Consider that Eve chooses 
her shuffling parameters s'l — s'2 — (this is one pos- 
sibility out of four.). Eve shuffles El which becomes 
El' = {\ei + (-l)'''i7r/4) (g) 16*2 + (-l)"27r/4)}, and sends 
it to Alice. 

(Q.3') After step (Q.3), Eve intercepts the returning 
qubit l(-l)'*''>7r/4 -|- (-l)''®''®^7r/4) and measures it to 
read the pre-key value I' — s'^ © fc © 6 — k (B b be- 
cause s[ = S2 = 0. She then encodes (-l)''®''®V/4 
onto one of E2. If Eve takes the first qubit, the qubit be- 
comes |0-|-(-l)''i7r/4-f (-l)''®''®^7r/4) and Bob measures 
l[ = si © fc © b. Otherwise, Bob measures ^3 = S2 © © &. 
Regardless l[ or I2, there would be a 25% error rate with 
I — Sb (B k (B b. This should be easily noticed in (Q.5). 

We have proved that the slightly modified KKKP pro- 
tocol becomes robust against the impersonation attack. 
One important point is that Alice should give special care 
not to give a chance for Eve to find the blocking factor 
before Eve returns encoded qubits to Bob in the step 
(Q.3'). Here, Eve may try to use spy pulses of different 
frequencies or different intensities in order to find this 
information. This kind of attempt should be filtered out 
by a careful design of the setupQ- For the case of co- 
herent state implementation, Alice can randomly check 
if the two pulses are of the same amplitude by sending 
them to a 50:50 beam splitter. When they are identical, 
all the photons should be detected at only one output 
port. If Eve uses two different pulses to get 6, her action 
will be detected by Ahce. 
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